Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
How could an attacker exploit this vulnerability? An unauthenticated attacker could send a specially crafted calendar invitation containing a malicious meeting link. A user would need to open the meeting and select the Join link; successful exploitation could allow script to run in the user's authenticated Outlook on the web session and access or modify mailbox data.
odgrso with <a href="https://gmo-cybersecurity.com/">GMO CyberSecurity by Ierae Inc</a>